Earlier quoted context omitted.
.. AWS surprisingly doesn't. Why is this surprising? AWS seem to know what they're doing in general, and this is obviously the right policy in this particular area.
How is it “obviously” the right policy? If implemented, console input would presumably be part of the AWS API, guarded with IAM permissions like everything else. If you have full IAM permissions, you can already take over any instance by temporarily attaching its disk to a different instance and modifying the data from there. (That requires rebooting, but so would takeover via console input.) Indeed, I’ve had to do e…
NordVPN confirms it was hacked
551–560 of 666 posts
Re: NordVPN confirms it was hacked
#552Re: NordVPN confirms it was hacked
#553Earlier quoted context omitted.
I have a slightly dissenting answer to these questions, in the form of an interactive Q&A website: https://faq.dhol.es/@Soatok/cryptography/which-vpn-service-w...
How is this not the top comment? Nobody should be using a VPN provider, full-stop. It is structurally impossible for anyone to verify their claims, they have more incentive to lie than your ISP does, and they're cheap and easy to set up, so the industry is a cesspool. You should assume that all of them are behaving badly.
A lot of ISPs openly collect user data, so I don't know how much that factor matters. And while I can go get a VPN, I can't just get another ISP.
Re: NordVPN confirms it was hacked
#554> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…
One presumes that because of NordVPN's business, they're colocating a server or two in many very many "POPs", presumably not all of them have tight controls on physical access. Its likely that there are none available in many areas where they seek to maintain a point of presence.
Re: NordVPN confirms it was hacked
#555Earlier quoted context omitted.
It doesn't make much sense to me, even with iDRAC/some other console access you don't really have access to OS unless you reboot & go to single user mode etc at which point they should be noticing their servers rebooting etc. would love more info
Why would they notice their server rebooting? And why would they not just assume it was a glitch or power failure?
Power failure would require both of the power feeds in the DC failing simultaneously and would be easily verified by contacting the DC and asking if they had any power outages reported at the time. Of course there are cheapskates who don't go for redundant power supplies so it's possible but would be indicated in the IPMI logs
Re: NordVPN confirms it was hacked
#556Earlier quoted context omitted.
They can do active attacks on you, as most people don't actively attempt to ban and absolutely block unencrypted connections (and there are also sometimes attacks on SSL stacks anyway); and like... SSL isn't really designed to protect the content of your connection anyway: due to size and timing attacks, people have deployed practical implementations of stuff like "figure out where I am looking at on Google Maps" and…
> SSL isn't really designed to protect the content of your connection anyway: due to size and timing attacks, people have deployed practical implementations of stuff like "figure out where I am looking at on Google Maps" and "figure out what movie I am watching on Netflix", and while I haven't seen a practical implementation of it yet, "learn too much about my search queries due to find-as-you-type". A VPN won't prot…
Re: NordVPN confirms it was hacked
#557Earlier quoted context omitted.
Yes, network KVMs are expected of any co-location center. You want to be able to access the console and the power switches of any real physical server without having to send someone out to the center, and is a common feature of most high end data centers. Even a lot of VM/cloud systems have some kind of virtual management console (Linode has their LISH system that lets you SSH in to console and Vultr/Digital Ocean ha…
.. AWS surprisingly doesn't. Why is this surprising? AWS seem to know what they're doing in general, and this is obviously the right policy in this particular area.
Re: NordVPN confirms it was hacked
#558Earlier quoted context omitted.
Yeah, Grammarly is creepy as hell. I've explicitly banned it (and similar services) at work. As for Youtube music, yup, that's undeniably a good deal. The music services should watch out, especially in younger demographics (I'm already 30+, Spotify premium user since 2009). Apple will probably push Music even harder and bundle that with their new video streaming. Spotify's really trying to become the defacto podcast…
> ...it's not super clear to me when tracks are clean encodes sourced from the proper music distribution ecosystem... Isn't that kind of the point? If you can't tell which is which without a visual cue (aka bias-generator) then they sound the same.
This isn't a comparison test. There's only one version uploaded. With only one version, it's hard to tell if many flaws you hear were introduced by sloppy uploading or if they were present in the master.
Re: NordVPN confirms it was hacked
#559Earlier quoted context omitted.
>Google can track you fairly effectively even if you’re behind a VPN. You don't know anything about my setup, so you have no basis for claiming this. On the other hand, if you have an exclusive sticky IP, you will be tracked all the time. And even if they don't do extensive fingerprinting right now, they can always go back and look at basic HTTP logs.
> You don't know anything about my setup, so you have no basis for claiming this. Sure, but the discussion isn't specifically about your setup, it's about the advertising claims that a VPN will help prevent tracking. Which is totally bunk. > On the other hand, if you have an exclusive sticky IP, you will be tracked all the time. And even if they don't do extensive fingerprinting right now, they can always go back and…
Re: NordVPN confirms it was hacked
#560Earlier quoted context omitted.
It depends on what you mean by 'hacking' a VPN. One assertion in this breach is that the NordVPN certificate private key was leaked, allowing anybody to spin up a NordVPN server that would pass HTTPS certificate validation (the cert is expired, it's currently unknown if the cert was valid for a period of time after it was compromised). This kind of an attack would let an attacker convince most users to download virus…
Let’s not forget that if they’ve got to a point where they can breach a private key they’re at a point where they’ve probably dumped hashed user creds and contact details, and probably gained persistence on breached hosts, too.
Not if the hacker only got access to relay servers.